Privacy Policy & Data Protection Notice
TRYNEX / HISAB · Effective: [DATE] · Version 1.0 · Under India's Digital Personal Data Protection Act, 2023
1. Who we are
TRYNEX ("HISAB", "we") operates a platform where businesses record credit sales and send purchase notes to customers. Data Fiduciary: TRYNEX [full legal name once registered] · Contact: [your email] · Grievance Officer: Gopal Agrawal · [grievance email]
2. What data we collect
- About buyers: name, mobile number, items purchased, amount, due date, payment status, dispute details (entered by the seller).
- About sellers: shop name, owner name, mobile number, UPI ID (for rewards), referral information.
- Technical: app usage, security logs, device/browser information.
3. Why we use it (purposes)
- To deliver the purchase note to the buyer and record confirmation/dispute.
- To send payment reminders from the seller.
- Only with the buyer's consent: to show a factual payment-history indicator ("₹X pending at Shop Y since [date]") to other participating businesses who independently check the same mobile number.
- To operate the seller rewards program (Kamai) and payouts.
- For security, dispute resolution, and legal compliance.
4. Your rights (DPDP Act)
- Access: ask what data we hold about you.
- Correction & completion: fix inaccurate data.
- Withdraw consent: stop the network payment-history indicator at any time.
- Erasure: request deletion where legally permitted.
- Grievance: complain to us first; if unresolved, to the Data Protection Board of India.
Write to [grievance email]. We respond within 30 days (internal target; statutory timelines apply).
5. Key protections
✔ Disputed records are excluded from all network indicators while under review
✔ No business can browse another business's customer list — only minimum factual indicators via individual number checks
✔ We never label anyone "defaulter" or "fraudster" — factual wording only
✔ We never sell raw customer lists, phone numbers, or transaction histories
✔ Data is encrypted in transit and at rest (Supabase/Postgres infrastructure)
6. Retention
Transaction records are retained for [X years — set 3 years] for accounting and legal-claim purposes, or until consent withdrawal + purpose completion, whichever is later. Security logs minimum 1 year (DPDP Rules).
7. Children's data
Our service is for business owners. We do not knowingly process children's data. If you believe a child's data exists here, contact us for immediate erasure.
8. Processors & transfers
We use Supabase (database, India region where available) and Vercel (hosting). Data may be stored/processed outside India only as permitted by law; we contractually bind processors to DPDP-equivalent safeguards.
9. Breach
If a data breach affects you, we will intimate you without delay and report to the Data Protection Board of India within 72 hours of discovery (DPDP Rules, 2025).
10. Policy changes
Version and date at top. Material changes will be notified in-app and on WhatsApp.